Vulnerability index

Browse CVEs

617 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Chrome HIGH 7.5
CVE-2015-1232

Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows …

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Chrome MEDIUM 5.0
CVE-2015-1225

PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vecto…

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Chrome HIGH 7.5
CVE-2015-1213

The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Chrome HIGH 7.5
CVE-2015-1360

Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-27
Chrome MEDIUM 5.0
CVE-2014-7946

The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips …

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome MEDIUM 5.0
CVE-2014-7947

OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome MEDIUM 5.0
CVE-2014-7945

OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome MEDIUM 5.0
CVE-2014-7944

The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle o…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome HIGH 7.5
CVE-2014-7938

The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly ha…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Chrome HIGH 7.5
CVE-2014-7937

Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to …

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Chrome HIGH 7.5
CVE-2014-7904

Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecif…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Chrome HIGH 7.5
CVE-2014-7903

Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of servic…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Chrome MEDIUM 5.0
CVE-2014-3201

core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a c…

Fix: after 38.0.2125.101
Fix from $1,600 2014-10-10
Chrome MEDIUM 5.0
CVE-2014-3198

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 valu…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Chrome MEDIUM 5.0
CVE-2014-3173

The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, whi…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Chrome MEDIUM 5.0
CVE-2014-3174

modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly co…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Android MEDIUM 5.1
CVE-2014-3100

Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arb…

No fix yet
Fix from $1,600 2014-07-02
Sketchup HIGH 9.3
CVE-2013-3662EPSS 32%

Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via a crafted color palette table…

Fix: after 8.0
Fix from $1,950 2014-07-01
Sketchup HIGH 9.3
CVE-2013-3664EPSS 30%

Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette tab…

Fix: after 8.0
Fix from $1,950 2014-07-01
Sketchup HIGH 9.3
CVE-2013-7388EPSS 13%

Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to ex…

Fix: after 8.0
Fix from $1,950 2014-07-01
Sketchup HIGH 9.3
CVE-2013-3663EPSS 32%

Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, allows remote attackers to exe…

Fix: after 8.0
Fix from $1,950 2014-06-13
Chrome HIGH 7.5
CVE-2014-3156

Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibl…

Fix: after 35.0.1916.152
Fix from $1,950 2014-06-11
Chrome HIGH 7.5
CVE-2014-3157

Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1…

Fix: after 35.0.1916.152
Fix from $1,950 2014-06-11
Chrome MEDIUM 5.0
CVE-2014-1746

The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently l…

Fix: after 35.0.1916.113
Fix from $1,600 2014-05-21
Chrome Os HIGH 7.5
CVE-2014-1710

The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS befo…

Fix: after 33.0.1750.149
Fix from $1,950 2014-03-16
Chrome Os HIGH 7.5
CVE-2014-1711

The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or p…

Fix: after 33.0.1750.149
Fix from $1,950 2014-03-16
Chrome HIGH 7.5
CVE-2013-6665

Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.175…

Fix: after 33.0.1750.144
Fix from $1,950 2014-03-05
Picasa HIGH 7.5
CVE-2013-5349

Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag …

Mitigation only
Fix from $1,950 2014-01-09
Picasa HIGH 7.5
CVE-2013-5357

Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that…

Mitigation only
Fix from $1,950 2014-01-09
Picasa HIGH 7.5
CVE-2013-5358

Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated u…

Mitigation only
Fix from $1,950 2014-01-09